Every CVE of the last six months, updated daily.
Published vulnerabilities straight from the National Vulnerability Database, with severity, CWE class and affected products. Search it, filter it, and see what landed today.
- 362 published in the last 24 hours
- 2,933 in the last 7 days
- 58,248 in the last six months
Source: NVD (National Vulnerability Database) · Updated Sep 23, 2026
Showing 2 of 2
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
CWE-159tornadoweb tornadoSuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request parameter is copied into the value of an HTML tag attribute which is an event handl
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.